--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2019-1f604fd2f2
2019-09-30 00:00:36.231210
--------------------------------------------------------------------------------Name        : sphinx
Product     : Fedora 31
Version     : 2.2.11
Release     : 13.fc31
URL         : http://sphinxsearch.com
Summary     : Free open-source SQL full-text search engine
Description :
Sphinx is a full-text search engine, distributed under GPL version 2.
Commercial licensing (e.g. for embedded use) is also available upon request.

Generally, it's a standalone search engine, meant to provide fast,
size-efficient and relevant full-text search functions to other
applications. Sphinx was specially designed to integrate well with SQL
databases and scripting languages.

Currently built-in data source drivers support fetching data either via
direct connection to MySQL, or PostgreSQL, or from a pipe in a custom XML
format. Adding new drivers (e.g. native support other DBMSes) is
designed to be as easy as possible.

Search API native ported to PHP, Python, Perl, Ruby, Java, and also
available as a plug-gable MySQL storage engine. API is very lightweight so
porting it to new language is known to take a few hours.

As for the name, Sphinx is an acronym which is officially decoded as SQL
Phrase Index. Yes, I know about CMU's Sphinx project.

--------------------------------------------------------------------------------Update Information:

Security fix for CVE-2019-14511
--------------------------------------------------------------------------------References:

  [ 1 ] Bug #1749188 - CVE-2019-14511 sphinx: no authentication and listens on 0.0.0.0 leads to information disclosure
        https://bugzilla.redhat.com/show_bug.cgi?id=1749188
--------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2019-1f604fd2f2' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Fedora 31: sphinx FEDORA-2019-1f604fd2f2

September 29, 2019
Security fix for CVE-2019-14511

Summary

Sphinx is a full-text search engine, distributed under GPL version 2.

Commercial licensing (e.g. for embedded use) is also available upon request.

Generally, it's a standalone search engine, meant to provide fast,

size-efficient and relevant full-text search functions to other

applications. Sphinx was specially designed to integrate well with SQL

databases and scripting languages.

Currently built-in data source drivers support fetching data either via

direct connection to MySQL, or PostgreSQL, or from a pipe in a custom XML

format. Adding new drivers (e.g. native support other DBMSes) is

designed to be as easy as possible.

Search API native ported to PHP, Python, Perl, Ruby, Java, and also

available as a plug-gable MySQL storage engine. API is very lightweight so

porting it to new language is known to take a few hours.

As for the name, Sphinx is an acronym which is officially decoded as SQL

Phrase Index. Yes, I know about CMU's Sphinx project.

Security fix for CVE-2019-14511

[ 1 ] Bug #1749188 - CVE-2019-14511 sphinx: no authentication and listens on 0.0.0.0 leads to information disclosure

https://bugzilla.redhat.com/show_bug.cgi?id=1749188

su -c 'dnf upgrade --advisory FEDORA-2019-1f604fd2f2' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/keys

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

FEDORA-2019-1f604fd2f2 2019-09-30 00:00:36.231210 Product : Fedora 31 Version : 2.2.11 Release : 13.fc31 URL : http://sphinxsearch.com Summary : Free open-source SQL full-text search engine Description : Sphinx is a full-text search engine, distributed under GPL version 2. Commercial licensing (e.g. for embedded use) is also available upon request. Generally, it's a standalone search engine, meant to provide fast, size-efficient and relevant full-text search functions to other applications. Sphinx was specially designed to integrate well with SQL databases and scripting languages. Currently built-in data source drivers support fetching data either via direct connection to MySQL, or PostgreSQL, or from a pipe in a custom XML format. Adding new drivers (e.g. native support other DBMSes) is designed to be as easy as possible. Search API native ported to PHP, Python, Perl, Ruby, Java, and also available as a plug-gable MySQL storage engine. API is very lightweight so porting it to new language is known to take a few hours. As for the name, Sphinx is an acronym which is officially decoded as SQL Phrase Index. Yes, I know about CMU's Sphinx project. Security fix for CVE-2019-14511 [ 1 ] Bug #1749188 - CVE-2019-14511 sphinx: no authentication and listens on 0.0.0.0 leads to information disclosure https://bugzilla.redhat.com/show_bug.cgi?id=1749188 su -c 'dnf upgrade --advisory FEDORA-2019-1f604fd2f2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
Product : Fedora 31
Version : 2.2.11
Release : 13.fc31
URL : http://sphinxsearch.com
Summary : Free open-source SQL full-text search engine

Related News